Aguara – Security scanner for AI agent skills and MCP servers
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.
Supply chain security scanner for MCP servers. Detect typosquats, CVEs, credential leaks, and dangerous permissions in your AI agent configs.
Think “Snyk for MCP configs”: Levenshtein-based typosquat detection, CVE lookups, hardcoded-credential scans and permission checks, plus CI-friendly exit codes. Auto-discovery for clients like Claude, Cursor and VS Code shows practical attention to workflows. It’s an early release — the value hinges on maintaining the package/CVE databases and tuning detection heuristics.
AI/platform engineers, security engineers, DevOps and CI/CD maintainers running MCP servers or agent platforms
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.
Lighthouse-style certification for MCP servers with trivy supply chain scanning.
Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
First security scanner for MCP configs as the protocol gains adoption.
Scanned 88K tools, found 537 malicious—solves real AI supply-chain vulnerability.